Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Human Resources HIGH 7.5
CVE-2026-46955

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Isupplier Portal HIGH 8.0
CVE-2026-46894

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Mysql Shell MEDIUM 6.5
CVE-2026-46869

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and…

Fix: after 9.7.0
Fix from $1,600 2026-06-17
Webcenter Content CRITICAL 9.3
CVE-2026-46785

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect…

Mitigation only
Fix from $2,300 2026-06-17
Webcenter Content CRITICAL 9.6
CVE-2026-46786

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect…

Mitigation only
Fix from $2,300 2026-06-17
Webcenter Content HIGH 8.0
CVE-2026-46787

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified MEDIUM 5.3
CVE-2016-20083

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabli…

No fix yet
Fix from $1,600 2026-06-15
Unclassified HIGH 7.1
CVE-2026-49396

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-si…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 7.1
CVE-2026-54359

MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled,…

Patch available
Fix from $1,950 2026-06-12
Unclassified HIGH 8.0
CVE-2026-48612

Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to…

Mitigation only
Fix from $1,950 2026-06-12
Notification Center HIGH 8.8
CVE-2025-58468

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerab…

Fix: 1.10.0.3291+
Fix from $1,950 2026-06-10
Unclassified MEDIUM 6.3
CVE-2026-39170

SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-8907

The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing no…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-8910

The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to m…

Mitigation only
Fix from $1,600 2026-06-09
Chrome MEDIUM 6.5
CVE-2026-11270

Inappropriate implementation in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a craft…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-05
Chrome HIGH 7.5
CVE-2026-11265

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HT…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-05
Chrome MEDIUM 6.5
CVE-2026-11214

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11200

Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11194

Inappropriate implementation in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTM…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11195

Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11148

Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11139

Inappropriate implementation in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11134

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11129

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11106

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11083

Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a cr…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11084

Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a cr…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11020

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Unclassified HIGH 8.8
CVE-2026-43985

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing adm…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified CRITICAL 9.8
CVE-2019-25729

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting P…

Mitigation only
Fix from $2,300 2026-06-04